Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Core system binary started by an unexpected parent

AN1076 describes the hollowing sequence — CreateProcess with CREATE_SUSPENDED, NtUnmapViewOfSection, VirtualAllocEx and WriteProcessMemory, then SetThreadContext and ResumeThread — and none of the three log sources in the strategy carries any step of it. Sysmon EventID 1 has no field for process creation flags, so the suspended start is invisible; EventID 10 does not fire because the injector creates the victim itself and already holds the handle, so it never calls OpenProcess; EventID 8 does not fire because execution resumes the child's existing primary thread rather than creating a remote one. What remains observable is the decoy itself, which is what MITRE's HollowedImageNamePattern knob points at, populated here not with a name list but with the small set of Windows binaries that have exactly one legitimate creator — svchost.exe and spoolsv.exe come from services.exe, lsass.exe and services.exe from wininit.exe, csrss.exe, wininit.exe and winlogon.exe from smss.exe — so any other parent is an anomaly on its face. The rule is written in Sysmon EventID 1 vocabulary (Image, ParentImage); on Security 4688 the equivalent fields are NewProcessName and ParentProcessName and Audit Process Creation must be enabled first, a mapping this rule does not carry. Prerequisite: Sysmon is not present in a default install. Two limits are structural: a hit is evidence of an anomalous launch, not of hollowing — masquerading under a system binary name produces the identical event — and a hollowed process created under a plausible parent, or hollowed into a decoy outside this list, is missed entirely. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0382, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Core system binary started by an unexpected parentid: 84eba238-f158-439f-bd5b-cc15136519c7status: experimentaldescription: |  AN1076 describes the hollowing sequence — CreateProcess with CREATE_SUSPENDED,  NtUnmapViewOfSection, VirtualAllocEx and WriteProcessMemory, then  SetThreadContext and ResumeThread — and none of the three log sources in the  strategy carries any step of it. Sysmon EventID 1 has no field for process  creation flags, so the suspended start is invisible; EventID 10 does not fire  because the injector creates the victim itself and already holds the handle,  so it never calls OpenProcess; EventID 8 does not fire because execution  resumes the child's existing primary thread rather than creating a remote one.  What remains observable is the decoy itself, which is what MITRE's  HollowedImageNamePattern knob points at, populated here not with a name list  but with the small set of Windows binaries that have exactly one legitimate  creator — svchost.exe and spoolsv.exe come from services.exe, lsass.exe and  services.exe from wininit.exe, csrss.exe, wininit.exe and winlogon.exe from  smss.exe — so any other parent is an anomaly on its face. The rule is written  in Sysmon EventID 1 vocabulary (Image, ParentImage); on Security 4688 the  equivalent fields are NewProcessName and ParentProcessName and Audit Process  Creation must be enabled first, a mapping this rule does not carry.  Prerequisite: Sysmon is not present in a default install. Two limits are  structural: a hit is evidence of an anomalous launch, not of hollowing —  masquerading under a system binary name produces the identical event — and a  hollowed process created under a plausible parent, or hollowed into a decoy  outside this list, is missed entirely.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0382, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1055/012  - https://attack.mitre.org/detectionstrategies/DET0382author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.defense-evasion  - attack.privilege-escalation  - attack.t1055.012logsource:  category: process_creation  product: windowsdetection:  selection:    Image|endswith:      - '\svchost.exe'      - '\spoolsv.exe'      - '\lsass.exe'      - '\services.exe'      - '\csrss.exe'      - '\wininit.exe'      - '\winlogon.exe'  filter_parent:    ParentImage|endswith:      - '\services.exe'      - '\wininit.exe'      - '\smss.exe'  condition: selection and not filter_parentfalsepositives:  - "Windows container hosts, where every container start brings up wininit.exe, services.exe, csrss.exe and svchost.exe under the container runtime rather than under the usual creator. On such a host this is the highest-volume match by a wide margin and needs a ParentImage exclusion for the runtime before the rule is usable at all. This is what sets the level."  - "Administrators and support scripts troubleshooting a wedged service by hand, for example launching svchost.exe with a service group from an elevated console or restarting the print spooler out of band, which puts cmd.exe or a shell under ParentImage."  - "Third-party software that ships a binary with one of these file names in its own directory and starts it from a vendor updater or service wrapper; the match is on file name, not on path, so a bundled spoolsv.exe or services.exe under Program Files matches the same way the real one would."  - "Imaging, sysprep and OS-deployment tooling, plus nested-session hosts such as Windows Sandbox and remote-desktop session brokers, all of which start session-level system processes from a launcher of their own."level: medium

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where ((FolderPath endswith "\\svchost.exe" or FolderPath endswith "\\spoolsv.exe" or FolderPath endswith "\\lsass.exe" or FolderPath endswith "\\services.exe" or FolderPath endswith "\\csrss.exe" or FolderPath endswith "\\wininit.exe" or FolderPath endswith "\\winlogon.exe") and not ((InitiatingProcessFolderPath endswith "\\services.exe" or InitiatingProcessFolderPath endswith "\\wininit.exe" or InitiatingProcessFolderPath endswith "\\smss.exe")))

Splunk · SPL

Run this as a search.

index=* ((Image="*\\svchost.exe" OR Image="*\\spoolsv.exe" OR Image="*\\lsass.exe" OR Image="*\\services.exe" OR Image="*\\csrss.exe" OR Image="*\\wininit.exe" OR Image="*\\winlogon.exe") AND NOT ((ParentImage="*\\services.exe" OR ParentImage="*\\wininit.exe" OR ParentImage="*\\smss.exe")))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE ((TO_LOWER(process.executable) LIKE "*\\\\svchost.exe" OR TO_LOWER(process.executable) LIKE "*\\\\spoolsv.exe" OR TO_LOWER(process.executable) LIKE "*\\\\lsass.exe" OR TO_LOWER(process.executable) LIKE "*\\\\services.exe" OR TO_LOWER(process.executable) LIKE "*\\\\csrss.exe" OR TO_LOWER(process.executable) LIKE "*\\\\wininit.exe" OR TO_LOWER(process.executable) LIKE "*\\\\winlogon.exe") AND NOT ((TO_LOWER(process.parent.executable) LIKE "*\\\\services.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\wininit.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\smss.exe")))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="7">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)(\\svchost\.exe$|\\spoolsv\.exe$|\\lsass\.exe$|\\services\.exe$|\\csrss\.exe$|\\wininit\.exe$|\\winlogon\.exe$)</field>    <field name="ParentImage" negate="yes" type="pcre2">(?i)(\\services\.exe$|\\wininit\.exe$|\\smss\.exe$)</field>    <description>Core system binary started by an unexpected parent</description>    <mitre>      <id>T1055.012</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.